FireEye 2019 Q1µç×ÓÓʼþÍþв»ã±¨£¬£¬£¬£¬£¬£¬£¬´¹µö¹¥»÷Ôö³¤17%£»£»£»£»£»Silex¿ÉÈÃIoTÉ豸±äש£¬£¬£¬£¬£¬£¬£¬ÒÑϰȾ2000¶ą̀É豸
°ä²¼¹¦·ò 2019-06-26
ƾ¾Ý±¾ÖܶþFireEye°ä²¼µÄ2019ÄêµÚÒ»¼¾¶Èµç×ÓÓʼþÍþв»ã±¨£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃHTTPSµÄ¶ñÒâURL±ÈÀýÔö³¤ÁË26%£¬£¬£¬£¬£¬£¬£¬¶ø´«Í³µÄ¸½¼þΪ¶ñÒâÈí¼þµÄµç×ÓÓʼþÔÚÎȲ½½µÂä¡£¡£¡£¡£¡£»£»£»£»£»ùÓÚ¶Ô13ÒÚ·âµç×ÓÓʼþµÄ·ÖÎö£¬£¬£¬£¬£¬£¬£¬¸Ã»ã±¨Ö¸³ö2019ÄêµÚÒ»¼¾¶ÈµÄÍøÂç´¹µö¹¥»÷±ÈÉÏÒ»¼¾¶ÈÔö³¤ÁË17%£¬£¬£¬£¬£¬£¬£¬×ܹ²Óнü30%µÄ¹¥»÷ÊÇ·ÂÕÕMicrosoft¡¢OneDrive¡¢Apple¡¢AmazonºÍPayPalµÈ³ÛÃûÆ·ÅÆ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Îļþ¹²Ïí·þÎñÔÚÕë¶ÔÆóÒµµÄÍøÂç¹¥»÷Öб»¸üƵÈÔµØÊ¹Ó㬣¬£¬£¬£¬£¬£¬Ô̺¬Google DriveºÍDropbox¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.fireeye.com/offers/rpt-email-threat.html
2¡¢¶ñÒâÈí¼þOSX/Linker£¬£¬£¬£¬£¬£¬£¬ÀûÓÃmacOSÖÐ佨²¹µÄGatekeeperÈÆ¹ý·ì϶
Intego°²È«×êÑÐÈËÔ±ÖÒ¸æ³ÆÐµĶñÒâÈí¼þOSX/LinkerÔÚÀûÓÃmacOSÖÐ佨¸´µÄGatekeeperÈÆ¹ý·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶¿ÉÔÚ²»ÏòÓû§ÏÔʾÈκÎÖÒ¸æÐÅÏ¢»òÒªÇó»ñµÃÐí¿ÉµÄÇé¿öÏÂÖ´Ðв»ÊÜÐÅÀµµÄ´úÂë¡£¡£¡£¡£¡£OSX/LinkerÉÐδÔÚÒ°±í³öÏÖ£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±Joshua Long°µÊ¾¸Ã¶ñÒâÈí¼þËÆºõ»¹ÔÚ¿ª·¢ÖУ¬£¬£¬£¬£¬£¬£¬¹ÌÈ»¶ñÒâÑù±¾ÀûÓÃÁË佨²¹µÄGatekeeperÈÆ¹ý·ì϶£¬£¬£¬£¬£¬£¬£¬µ«Ã»Óдӹ¥»÷ÕߵķþÎñÆ÷¸ßµÍÔØÈκζñÒâÀûÓ÷¨Ê½¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/06/macos-malware-gatekeeper.html
3¡¢Ð¶ñÒâÈí¼þSilex¿ÉÈÃIoTÉ豸±äש£¬£¬£¬£¬£¬£¬£¬ÒÑϰȾ2000¶ą̀É豸
Akamai×êÑÐÔ±Larry Cashdollar·¢ÏÖжñÒâÈí¼þSilexÔÚ½øÐй¥»÷£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ»á²Á³ýIoTÉ豸µÄ¹Ì¼þ£¬£¬£¬£¬£¬£¬£¬É¾³ýÆä´æ´¢¡¢·À»ðǽ¹æ¶¨ÒÔ¼°ÍøÂçÅäÖ㬣¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂÉ豸ÖÕ³¡ÔËÐÓ×£¡£¡£¡£¡£ÒªÏ븴ÔÉ豸µÄÔËÐУ¬£¬£¬£¬£¬£¬£¬Êܺ¦Õß±ØÐëÊÖ¶¯³ÁÐÂ×°ÖÃÉ豸¹Ì¼þ¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£¿ÉÄÜ»áÓÐһЩÊܺ¦ÕßÒÔΪÓöµ½ÁËÓ²¼þ¹ÊÕ϶øÅׯúÉ豸¡£¡£¡£¡£¡£¹¥»÷ÆðÔ´ÊÇλÓÚÒÁÀʵķþÎñÆ÷£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖØÒªÍ¨¹ýÒÑÖªµÄIoTÉ豸ĬÈϵǼʹ´¦»ñµÃ¶ÔÉ豸µÄ½Ó¼û¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÈÔÔÚ½øÐÐÖУ¬£¬£¬£¬£¬£¬£¬ÒÑÓг¬¹ý2000̨É豸±»±äש¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/new-silex-malware-is-bricking-iot-devices-has-scary-plans/
4¡¢ÐÂÀ¬»øÓʼþ»î¶¯£¬£¬£¬£¬£¬£¬£¬ÀûÓÃISOÎļþ´«²¼LokiBotºÍNanocore
Netskope×êÑÐÈËÔ±ÔÚ4Ô·ݹ۲쵽¶à¸ö¶ñÒâ¹¥»÷»î¶¯ÀûÓÃISO¾µÏñÎļþ´«²¼LokiBotºÍNanocore£¬£¬£¬£¬£¬£¬£¬ÕâЩISOÎļþ×ã¹»Ó×£¬£¬£¬£¬£¬£¬£¬ÒÔÖÁÓÚÄܹ»·ÅÈëµç×ÓÓʼþµÄ¸½¼þÖÓ×£¡£¡£¡£¡£Í¨³£Çé¿öÏÂISOÎļþÒª´óÓÚ100MB£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷»î¶¯ÖеÄISOÎļþµÄ´óÓ×´Ó1MBµ½2MB²»µÈ¡£¡£¡£¡£¡£´Ó¹¥»÷ÕߵĽǶÈÀ´¿´£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃISOÎļþºÜÓÐÒâ˼£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´óÎÞÊýÏÖ´ú²Ù×÷ϵͳÄܹ»ÔÚÓû§½Ó¼û¾µÏñʱ×Ô¶¯¹ÒÔØ¾µÏñ²¢ÏÔʾÆäÄÚÈÝ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬³öÓÚ»úÄÜÔÒò£¬£¬£¬£¬£¬£¬£¬Ò»Ð©°²È«½â¾ö¹æ»®Æ«²îÓÚ½«ISOÎļþÁÐÈë°×Ãûµ¥£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹ËüÃDz»Ò×±»¼ì²â¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/malspam-campaigns-hide-infostealers-in-iso-image-files/
5¡¢·ÆÄá¿Ë˹µçÆø½¨¸´AutomationworxÌ×¼þÖеĶà¸ö·ì϶
µÂ¹ú·ÆÄá¿Ë˹µçÆø£¨Phoenix Contact£©½¨¸´Automationworx×Ô¶¯»¯Ì×¼þÖеĶà¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ö¸Õëδ³õʼ»¯·ì϶£¨CVE-2019-12870£©¡¢use-after-free·ì϶£¨CVE-2019-12871£©ºÍÔ½½ç¶Á·ì϶£¨CVE-2019-12869£©¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬PC Worx 1.86¼°Ö®Ç°°æ±¾¡¢PC Worx Express 1.86¼°Ö®Ç°°æ±¾ºÍConfig+ 1.86 ¼°Ö®Ç°°æ±¾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/flaws-phoenix-contact-automationworx-allow-code-execution-malicious-files
6¡¢ABB½¨¸´×Ô¶¯»¯ÏµÍ³HMIÖеÄÊ®¶à¸ö·ì϶
DarkMatter xen1thLabs×êÑÐÍŶӷ¢ÏÖÈðÊ¿¹¤Òµ¼¼Êõ¹«Ë¾ABBµÄHMI²úÆ·ÖеÄ12¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¿Éµ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡¢ËÁÒâ´úÂëÖ´ÐкÍÐÅϢй¶µÈ¡£¡£¡£¡£¡£·ì϶ÁìÓòº¸Ç¹ýÆÚµÄÈí¼þ×é¼þ¡¢Ó²±àÂëµÄÖÎÀíԱʹ´¦¡¢²»°²È«µÄÈí¼þ¸üлúÔì¡¢FTP·þÎñÆ÷ÖеÄõè¾¶±éÀú¡¢»Ø¾ø·þÎñÒÔ¼°´úÂëÖ´Ðеȣ¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâÒªÇóÀ´ÀûÓÃÕâЩ·ì϶¡£¡£¡£¡£¡£³É¹¦ÀûÓ÷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»á×èÖ¹¶ÔÊÜÓ°Ïìϵͳ½ÚµãµÄºÏ·¨½Ó¼û¡¢Ô¶³ÌÖÕ³¡ÏµÍ³½Úµã¡¢½ÚÔìϵͳ½Úµã»òÔÚϵͳ½ÚµãÖвåÈëºÍÔËÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/abb-patches-many-vulnerabilities-hmi-products


¾©¹«Íø°²±¸11010802024551ºÅ